Skip to main content

Vendor/product archive

manageengine / servicedesk_plus CVEs

Beta · best-effort

10 CVEs tagged to manageengine / servicedesk_plus0 Critical, 2 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2015-1480

Published Feb 4, 2015

ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive ticket information via a (1) getTicketData action to servlet/A…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2585

Published Aug 12, 2012

Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ServiceDesk Plus 8.1 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body w…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1510

Published Sep 20, 2011

Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus (SDP) before 8012 allows remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1509

Published Sep 20, 2011

The encryptPassword function in Login.js in ManageEngine ServiceDesk Plus (SDP) 8012 and earlier uses a Caesar cipher for encryption of passwords in cookies, which makes it easier…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2757

Published Jul 17, 2011

Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2756

Published Jul 17, 2011

FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to read files from a specific directory via…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2755

Published Jul 17, 2011

Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remote attackers to read arbitrary files via unspecified vector…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1